Ransomcrow Ransomware 🔐 (. Encrypted File) — Removal Guide

Ransomcrow virus: what is known so far?

Ransomcrow will add its specific .encrypted extension to every file’s name. For example, a file entitled “photo.jpg” will be turned into “photo.jpg.encrypted”. Likewise, the Excel sheet named “table.xlsx” will be altered to “table.xlsx.encrypted”, and so forth.

In each folder that contains the encoded files, a readme.txt file will appear. It is a ransom money memo. Therein you can find information about the ways of contacting the racketeers and some other information. The ransom note usually contains a description of how to purchase the decryption tool from the racketeers. That is how they do it.

NameRansomcrow Virus
Extension.encrypted
Ransomware notereadme.txt
Ransom€50
Detection1TrojanDownloader:Win32/Waledac.C, Win32:SMSSend-ADN [Trj], Ransom:Win32/StopCrypt.PCG!MTB
SymptomsYour files (photos, videos, documents) have a .encrypted extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Ransomcrow virus

The readme.txt file accompanying the Ransomcrow ransomware provides the following frustrating information:

All of your files have been encrypted
Your computer was infected with a ransomware virus. Your files have been encrypted and you won\'t
be able to decrypt them without our help.

What can I do to get my files back? You can buy the decrypter, it will leave your pc as it was before the encryption.

The price is 50€

You can buy cryptos here
Coinmama - hxxps://
Bitpanda - hxxps://

Payment informationAmount: 0.1473766 BTC
Bitcoin Address:  1Cee1QKq46myiLVL1v1y5gq751piPGGHNs

In the picture below, you can see what a folder with files encrypted by the Ransomcrow looks like. Each filename has the “.encrypted” extension added to it.

That is how encrypted “.encrypted” files look.

How did my machine catch Ransomcrow ransomware?

Nowadays, there are three most popular ways for hackers to have the Ransomcrow virus working in your digital environment. These are email spam, Trojan infiltration and peer-to-peer networks.

If you access your mailbox and see emails that look like familiar notifications from utility services providers, delivery agencies like FedEx, Internet providers, and whatnot, but whose mailer is unknown to you, be wary of opening those emails. They are very likely to have a viral item attached to them. Therefore, it is even more dangerous to download any attachments that come with emails like these.

Another option for ransom hunters is a Trojan horse scheme2. A Trojan is an object that infiltrates into your PC pretending to be something legal. For example, you download an installer of some program you need or an update for some software. However, what is unpacked turns out to be a harmful agent that corrupts your data. As the update wizard can have any title and any icon, you have to make sure that you can trust the resource of the things you’re downloading. The best thing is to use the software developers’ official websites.

As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded files with the anti-malware utility as soon as the downloading is finished.

Marcus Vance

Marcus Vance

Cybersecurity & Digital Privacy Researcher

Marcus Vance is a cybersecurity auditor and technology writer dedicated to educating the public about online safety, data privacy regulations, enterprise security, and emerging cyber threats.

Share this article
Twitter Facebook Pinterest